ServiceNow fixes three critical code injection vulnerabilities
Source headline: ServiceNow Patches 3 Critical Code Injection Vulnerabilities
Intelligence Summary
ServiceNow has released patches addressing three critical code injection vulnerabilities. An attacker could exploit the security defects to execute arbitrary code. Successful exploitation could also allow attackers to access or tamper with data. The issues are described as code injection vulnerabilities that require remediation. Users of ServiceNow should apply the available patches promptly.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.